Developer Tools
File hash checker.
Pick a file to get its SHA-256, SHA-1, SHA-384, SHA-512 and MD5 checksums, then paste the value the publisher lists to see whether they match. The file is read in your browser and never uploaded.
Input
Checksums
Choose a file to compute its checksums.
About this file hash checker
A checksum is a short fingerprint of a file's exact bytes. Software publishers list one next to a download so you can confirm the file you received is the file they built: if even one byte differs, the fingerprint is completely different.
How to verify a download
- Find the checksum on the publisher's own download page and note which algorithm it is (usually SHA-256).
- Choose the downloaded file here and paste the published value into the comparison box.
- A match means the file is byte-for-byte what the publisher hashed. No match means a damaged download or a different file.
Which algorithm?
- SHA-256 and SHA-512 are current and collision-resistant. Prefer them whenever a publisher offers them.
- SHA-1 and MD5 are broken for security because deliberate collisions can be built. They still catch accidental corruption, and many older sites only list them.
- A checksum from the same page you downloaded from proves integrity, not trust: an attacker who replaces the file can replace the number too. Prefer a checksum or signature published through a separate channel.
Commands that give the same result
shasum -a 256 file # macOS / Linux
sha256sum file # Linux
Get-FileHash file -Algorithm SHA256 # Windows PowerShell
certutil -hashfile file SHA256 # Windows cmd
Limits
The file is read into memory, so the limit is 500 MB. SHA algorithms use your browser's built-in Web Crypto; MD5 is computed by a small in-page routine because Web Crypto does not offer it. Nothing is uploaded.
FAQ
How do I find the hash value of a file?
Choose the file above. All five checksums appear at once. To do it from a terminal use shasum -a 256 file on macOS, sha256sum file on Linux or Get-FileHash file in PowerShell.
Does the checker upload my file?
No. The file is read by your browser and hashed on your device. This page loads no advertising or analytics scripts.
Why does my hash not match?
Common causes: an interrupted or corrupted download, comparing a different algorithm, comparing the checksum of the archive against its contents, or a line-ending conversion. Download again and compare the same algorithm.
Source
- NIST FIPS 180-4, Secure Hash Standard (SHA-1, SHA-2): csrc.nist.gov.
- RFC 1321, The MD5 Message-Digest Algorithm: rfc-editor.org/rfc/rfc1321; RFC 6151 on MD5 collision weaknesses.